| |
May 25, 2026
|
|
|
|
|
IAAS 256 - Windows Digital Forensics 3 Credits This course provides a comprehensive survey of the technical knowledge of the Windows operating system essential for any digital forensic analyst. Students will gain in-depth knowledge of Windows system architecture, file systems, and user activities. They will learn to effectively collect and analyze digital evidence from Windows-based systems, including user activity logs, software artifacts, and system configuration data. Additionally, students will conduct hands-on digital forensic investigations, applying their knowledge to simulate real-world scenarios and analyze evidence to draw conclusions. Prerequisite(s): IAAS 221 and NETW 101 Course Learning Outcomes: 1. Create a technical forensic report.
2. Interpret Windows system logs, event logs, and registry keys for potential user actions and system changes.
3. Implement the forensic preservation process, including imaging Windows-based systems, hashing techniques for data integrity, and secure storage of digital evidence.
4. Describe the architecture and components of the Windows operating system, including system processes, file systems, and registry structure.
5. Identify common Windows forensic artifacts, such as event logs, prefetch files, and system restore points.
Add to Catalog (opens a new window)
|
|